[squid-users] benefits of using ext_kerberos_ldap_group_acl instead of ext_ldap_group_acl

Simon Staeheli sis at open.ch
Tue Jan 20 12:38:56 UTC 2015


> Whatever floats your boat. The point of the Addon/Plugin/helpers API
> is that you can use scripts if thy serve your needs better.
> 
> All the usual Open Source benefits of "many eyeballs" and somebody
> else doing code maintenance for you applies to using a bundled helper
> over a custom written one.
> 
> Beyond that the kerberos helper also provides automatic detection of
> which LDAP server to use via mutiple auto-configuration methods.
> 
> If you can demonstrate that the ext_kerberos_ldap_group_acl does
> provides a superset of the functionality of ext_ldap_group_acl helper
> then I can de-duplicate the two helpers.
> 
> Amos

Thanks for the hint regarding automatic detection of LDAP servers. I am 
just trying to find what the differences between the two helpers are and 
which one does fit my needs better. Any others?

Do you know anything about the feature in ext_kerberos_ldap_group_acl 
mentioned by Markus Moeller in an earlier post?

"I have a new method in my squid 3.4 patch which uses the Group
Information MS is putting in the ticket. This would eliminate the ldap
lookup completely." 
(http://www.squid-cache.org/mail-archive/squid-users/201309/0046.html)

Simon







More information about the squid-users mailing list